Expert Advice Community

Guest

RTO for critical application

  Quote
Guest
Guest user Created:   Feb 24, 2018 Last commented:   Feb 24, 2018

RTO for critical application

Is there an RTO for critical application? If yes, who defines this?
0 0

Assign topic to the user

ISO 27001 DOCUMENTATION TOOLKIT

Step-by-step implementation for smaller companies.

ISO 27001 DOCUMENTATION TOOLKIT

Step-by-step implementation for smaller companies.

Expert
Rhand Leal Feb 24, 2018

Answer: There is no standard or default Recovery Time Objective (RTO) that can be attributed to an application, because the RTO value is based on the results of a Business Impact Analysis (BIA), which is unique for each organization context. The definition of RTO can be made by the person responsible by the application, considering the inputs of interested parties impacted by a disruption on application operation (e.g., customers, regulators, etc.), and it is approved by top management.

These materials will provide you further explanation about RTO and BIA :
- What is the difference between Recovery Time Objective (RTO) and Recovery Point Objective (RPO)? https://advisera.com/27001academy/knowledgebase/what-is-the-difference-between-recovery-time-objective-rto-and-recovery-point-objective-rpo/
- Implementing Business Impact Analysis according to ISO 22301 [free webi nar on demand] https://advisera.com/27001academy/webinar/implementing-business-impact-analysis-according-to-iso-22301-free-webinar-on-demand/

Quote
0 0

Comment as guest or Sign in

HTML tags are not allowed

Feb 24, 2018

Feb 24, 2018